CVE-2022-33874

An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in SSH login components of FortiTester 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an unauthenticated remote attacker to execute arbitrary command in the underlying shell.
References
Link Resource
https://fortiguard.com/psirt/FG-IR-22-237 Vendor Advisory
Configurations

Configuration 1

cpe:2.3:a:fortinet:fortitester:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortitester:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortitester:*:*:*:*:*:*:*:*

Information

Published : 2022-10-18 03:15

Updated : 2022-10-21 12:59


NVD link : CVE-2022-33874

Mitre link : CVE-2022-33874

Products Affected
No products.
CWE